Netgate Discussion Forum
    • Categories
    • Recent
    • Tags
    • Popular
    • Users
    • Search
    • Register
    • Login

    Multiwan and DNS

    Scheduled Pinned Locked Moved Routing and Multi WAN
    10 Posts 3 Posters 3.9k Views
    Loading More Posts
    • Oldest to Newest
    • Newest to Oldest
    • Most Votes
    Reply
    • Reply as topic
    Log in to reply
    This topic has been deleted. Only users with topic management privileges can see it.
    • W
      Wasca
      last edited by

      Hi

      I have 2 WAN connections. WAN is ADSL2+ PPPOE (with static IP). WAN2 (OPT2) is a static IP.

      I've also got a LAN subnet (192.168.1.0/24) and another user subnet on OPT3 (192.168.3.0/24).

      I'm getting a little confused with the DNS issues. I want users on both subnets to use the WAN for HTTP traffic and WAN2 for other services like out going VNC sessions. What do I set the LAN users DNS address to? My first guess for LAN users is 192.168.1.1 (PFsense LAN IP), but what if WAN goes down and I want to use WAN2 for these users? How are they meant to do DNS lookups when they have 192.168.1.1 (which is using WAN DNS servers) set as their default DNS server?

      Next is OPT3 subnet, what do I set users on this network DNS server to? 192.168.3.1? what if they need to use WAN2 to do a DNS lookup?

      Thanks

      1 Reply Last reply Reply Quote 0
      • GruensFroeschliG
        GruensFroeschli
        last edited by

        Search the forum. This has been discussed.
        In short: If you want to use DNS servers on WAN2 you need to set a static route for the IP of you DNS pointing to your second gateway.

        We do what we must, because we can.

        Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

        1 Reply Last reply Reply Quote 0
        • W
          Wasca
          last edited by

          I'm a little confused?

          How does setting a static route to a DNS server IP help?

          1 Reply Last reply Reply Quote 0
          • GruensFroeschliG
            GruensFroeschli
            last edited by

            you need to set a static route for the IP of you DNS pointing to your second gateway.

            All traffic for this IP will be forced out the WAN2.

            We do what we must, because we can.

            Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

            1 Reply Last reply Reply Quote 0
            • W
              Wasca
              last edited by

              Ok that makes sense, but does not really clear up the issue from my original post.

              If the WAN goes down (or say the DNS server IP on the WAN link) how can clients on the LAN and OPT3 networks do DNS lookups if all these clients DNS settings are pointing to the IP address of the PFSense interface, 192.168.1.1 for LAN and 192.168.3.1 for OPT3?

              Can this be overcome by putting a DNS IP for WAN and WAN2 in the general settings page? and then using static routes, is that what you mean?

              1 Reply Last reply Reply Quote 0
              • GruensFroeschliG
                GruensFroeschli
                last edited by

                yes :)

                We do what we must, because we can.

                Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

                1 Reply Last reply Reply Quote 0
                • W
                  Wasca
                  last edited by

                  How does PFSense then know to use the other secondary DNS IP address?

                  1 Reply Last reply Reply Quote 0
                  • H
                    hoba
                    last edited by

                    Like every other system in the world. If the primary DNS doesn't answer it requests the information form the secondary DNS. This is just the way how DNS works  ;)

                    1 Reply Last reply Reply Quote 0
                    • GruensFroeschliG
                      GruensFroeschli
                      last edited by

                      Guess ;)

                      (when the primary is down :D)

                      Afaik you can add a third and a fourth DNS-entry in the config.xml.
                      So you can have a primary and secondary entry for for the first interface, and a tertiary and quaternary on the second interface.

                      We do what we must, because we can.

                      Asking questions the smart way: http://www.catb.org/esr/faqs/smart-questions.html

                      1 Reply Last reply Reply Quote 0
                      • W
                        Wasca
                        last edited by

                        Afaik you can add a third and a fourth DNS-entry in the config.xml.
                        So you can have a primary and secondary entry for for the first interface, and a tertiary and quaternary on the second interface.

                        That's brilliant, I'll be adding all my DNS IP's in then, and adding static routes to them.

                        Thanks for clearing all that up for me.

                        1 Reply Last reply Reply Quote 0
                        • First post
                          Last post
                        Copyright 2025 Rubicon Communications LLC (Netgate). All rights reserved.